SecEng Attack · Labs
Agent Tool Permission Analyzer
Paste your agent tool configuration JSON and get deterministic permission security findings. No LLM required. Detects missing approval gates, broad scopes, unsafe identities, and dangerous side effects.
- • Permission scope analysis: read-only vs write-broad vs admin
- • Side effect detection: email, record modification, privilege changes, code execution
- • Approval gate gaps: side-effecting actions without confirmation requirements
- • Execution identity: unknown, service account, system admin risks
- • MCP tool schema quality: ambiguous descriptions, unbounded arguments
15 security rules
Across 6 risk categories
Structured JSON input
Works with any agent config format
OWASP LLM06
Excessive Agency coverage
No LLM calls
Fully deterministic
Load example:
Next step
Need a full agent security review?
We assess AI agent trust boundaries, tool permission design, approval architecture, and blast radius — and produce findings mapped to OWASP LLM Top 10 and NIST AI RMF.